NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date far in the future), when encountered by the autoindex module.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade nginx | Jun 9, 2021 | Jun 6, 2021 |
| Huawei Euleros 2_0_sp2 | — | Upgrade nginx | Sep 16, 2021 | Jun 6, 2021 |
| Huawei Euleros 2_0_sp3 | — | Upgrade nginx | Oct 26, 2021 | Jun 6, 2021 |
| Huawei Euleros 2_0_sp8 | — | Upgrade nginx-all-modulesUpgrade nginx-mod-mailUpgrade nginx-mod-streamUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-http-perlUpgrade nginx-mod-http-image-filterUpgrade nginxUpgrade nginx-filesystem | Sep 24, 2021 | Jun 6, 2021 |
| Nginx | — | Upgrade to nginx version 1.13.6 | Feb 10, 2023 | Jun 6, 2021 |
| Ubuntu | — | Upgrade nginx (Ubuntu Pro) | Oct 19, 2021 | Jun 6, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub